# On the safety of installing contributed nodes

**URL:** <https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556>\
**Category:** General\
**Created:** [12 May 2022 11:15 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556 "2022-05-12T11:15:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [12 May 2022 11:15 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/1 "2022-05-12T11:15:34Z")

</div>

Simply put, are there any security concerns with using Manage Palette to install node-red-contrib-blah-blah?

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [12 May 2022 12:15 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/2 "2022-05-12T12:15:33Z")

</div>

Exactly the same as installing anything from [npmjs.org](http://npmjs.org) (buyer beware)

The Node-RED project does not (currently\*) do any vetting of what is submitted and presented by the catalogue.

\*This is not an announcement of anything that is coming, but is a concept that has been discussed in the past, but it would likely have to be a paid for service as it would be time consuming and especially if any sort of liability was attached.

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [12 May 2022 12:19 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/3 "2022-05-12T12:19:52Z")

</div>

But if you find anything that you think is a risk/problem do report it as things can be blocked/removed if needed.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [12 May 2022 12:33 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/4 "2022-05-12T12:33:46Z")

</div>

> The Node-RED project does not do any vetting of what is submitted and presented by the catalogue

Hmm that's what I thought.

On my Raspberry, Node-red runs as the user pi, which has sudo access without a password.  
So I presume any node installed effectively has root privileges.  
I know passwordless sudo is of itself a security issue.

What's the extent of any risk? Does the installation process run code provided with a node, or only when you include it in a flow?

Presumably if a contributor's GitHub account was compromised, malicious code could be inserted in a previously safe node?

---

<div class="post-metadata">

**Author:** ![hardillb](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/hardillb/32/12373_2.png) [@hardillb](https://discourse.nodered.org/u/hardillb)\
**Post date:** [12 May 2022 13:14 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/5 "2022-05-12T13:14:51Z")

</div>

> [@jbudd](#):
>
> What's the extent of any risk? Does the installation process run code provided with a node, or only when you include it in a flow?

Again same as with npm. It is possible for packages to include install hook scripts ([scripts | npm Docs](https://docs.npmjs.com/cli/v8/using-npm/scripts#pre--post-scripts)) so just installing can be enough to compromise a machine.

The problem is more the npm account than github (though github owns [npmjs.org](http://npmjs.org) thes days) which is why they are basically forcing 2fa on everybody slowly at the moment. But if they have automation setup then compromising the GH account could be enough.

---

<div class="post-metadata">

**Author:** ![ncherry](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ncherry/32/27_2.png) [@ncherry](https://discourse.nodered.org/u/ncherry)\
**Post date:** [12 May 2022 18:50 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/6 "2022-05-12T18:50:17Z")

</div>

I've been curious about this also. Is there a way for the developer to sign the flow/library? I wonder how you could handle this with a team?

Sorry thinking out loud.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [11 July 2022 18:51 UTC](https://discourse.nodered.org/t/on-the-safety-of-installing-contributed-nodes/62556/7 "2022-07-11T18:51:16Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
